Identity risk and cyber access risk engine

    公开(公告)号:US11157629B2

    公开(公告)日:2021-10-26

    申请号:US16867619

    申请日:2020-05-06

    申请人: SAIX Inc.

    摘要: A system for managing cyber security risks includes a memory storing instructions and a processor that executes the instructions to perform operations. The operations include receiving raw entity data for one or more entities from a source system and converting the raw entity data to processed entity data having a format different from the first entity data. The operations include extracting attributes for the entities from the processed entity data and generating an initial risk score for a selected entity based on an entity initial attribute associated with that entity. The operations also include receiving a rule for determining a rule-based risk score and generating a rule-based risk score for the selected entity based on the entity attribute of the selected entity. Additionally, the operations include generating a risk score for the selected entity based on the initial and rule-based risk scores.

    Anticipatory cybersecurity
    2.
    发明授权

    公开(公告)号:US12124589B2

    公开(公告)日:2024-10-22

    申请号:US17704342

    申请日:2022-03-25

    申请人: SAIX INC.

    IPC分类号: G06F21/00 G06F21/57

    CPC分类号: G06F21/577 G06F2221/034

    摘要: A cybersecurity system for an information and technology system is presented. The cybersecurity system includes: a risk engine that detects past events in the information and technology system, the risk engine including an electronically stored set of rules characterizing events; a prevention engine that models events in the information and technology system, the prevention engine including a model builder, the prevention engine communicatively coupled to the risk engine; and a user interface communicatively coupled to the risk engine and to the prevention engine; where the model builder is configured to build at least one attack tree based on a past event detected by the risk engine and a potential event modeled by the prevention engine, and where the cybersecurity system is configured to report the at least one attack tree through the user interface, such that a future event depicted in the at least one attack tree can be remediated.

    ANTICIPATORY CYBERSECURITY
    3.
    发明申请

    公开(公告)号:US20220309166A1

    公开(公告)日:2022-09-29

    申请号:US17704342

    申请日:2022-03-25

    申请人: SAIX INC.

    IPC分类号: G06F21/57

    摘要: A cybersecurity system for an information and technology system is presented. The cybersecurity system includes: a risk engine that detects past events in the information and technology system, the risk engine including an electronically stored set of rules characterizing events; a prevention engine that models events in the information and technology system, the prevention engine including a model builder, the prevention engine communicatively coupled to the risk engine; and a user interface communicatively coupled to the risk engine and to the prevention engine; where the model builder is configured to build at least one attack tree based on a past event detected by the risk engine and a potential event modeled by the prevention engine, and where the cybersecurity system is configured to report the at least one attack tree through the user interface, such that a future event depicted in the at least one attack tree can be remediated.